Executive brief
Cloud Foundry BOSH, a tool used for deploying and managing large-scale cloud applications, contains a security flaw in how it processes uploaded software packages. An attacker with administrative privileges could upload a specially crafted package file that executes unauthorized commands on the BOSH Director server. This could lead to a full system takeover, allowing the attacker to disrupt operations or access sensitive data across the entire cloud environment.
Technical details
An OS command injection vulnerability exists in the BOSH PackagePersister.validate_tgz method. The component constructs a shell command using the 'name' field from the release.MF file found within an uploaded tarball without applying proper shell escaping. This string is passed to Bosh::Common::Exec.sh, which executes via /bin/sh -c. While validation logic exists to restrict package names, the shell-out occurs in the save_package_source_blob path before the validation is triggered. An attacker with 'bosh.releases.upload' or 'bosh.admin' privileges can exploit this by crafting a package name containing shell metacharacters (e.g., semicolons or backticks) to achieve arbitrary code execution on the BOSH Director. The issue is fixed in BOSH v282.1.12.
Affected products
- Cloud Foundry Foundation BOSH versions prior to v282.1.12
Timeline
- 2026-06-02: advisory: Initial advisory published by Cloud Foundry Foundation
- 2026-06-04: disclosed: CVE published to NVD
- 2026-06-02: patched: Fixed in BOSH v282.1.12